nerdexam
CompTIA

CS0-003 · Question #302

The Chief Information Security Officer for an organization recently received approval to install a new EDR solution. Following the installation, the number of alerts that require remediation by an ana

The correct answer is A. SOAR B. SIEM. EDR Alert Overload: Centralizing Security Workload SOAR (A) and SIEM (B) are the correct answers because they directly address the challenge of centralizing and managing a high volume of security alerts. A SIEM aggregates and correlates log/alert data from multiple sources (inclu

Submitted by amina.ke· Mar 6, 2026Security operations

Question

The Chief Information Security Officer for an organization recently received approval to install a new EDR solution. Following the installation, the number of alerts that require remediation by an analyst has tripled. Which of the following should the organization utilize to best centralize the workload for the internal security team? (Choose two.)

Options

  • ASOAR
  • BSIEM
  • CMSP
  • DNGFW
  • EXDR
  • FDLP

How the community answered

(31 responses)
  • A
    77% (24)
  • C
    3% (1)
  • D
    13% (4)
  • F
    6% (2)

Explanation

EDR Alert Overload: Centralizing Security Workload

SOAR (A) and SIEM (B) are the correct answers because they directly address the challenge of centralizing and managing a high volume of security alerts. A SIEM aggregates and correlates log/alert data from multiple sources (including the new EDR) into a single dashboard, giving analysts a unified view. A SOAR complements this by automating repetitive response tasks and orchestrating workflows, dramatically reducing the manual effort needed to remediate the tripled alert volume.

Why the distractors are wrong:

  • MSP (C) is a Managed Service Provider - an outsourced IT vendor, not a centralization tool
  • NGFW (D) is a Next-Generation Firewall - a perimeter security tool, not an alert management solution
  • XDR (E) could centralize detection, but it replaces the EDR rather than helping manage its output alongside existing infrastructure
  • DLP (F) is Data Loss Prevention - focused on data exfiltration, unrelated to alert centralization

Memory Tip: Think "SIEM sees everything, SOAR sorts everything" - when alert fatigue strikes, you need one tool to collect (SIEM) and one to act automatically (SOAR). If a question mentions overwhelming alerts for an internal team, SIEM + SOAR is almost always the answer.

Topics

#SIEM#SOAR#Security Operations#Alert Management

Community Discussion

No community discussion yet for this question.

Full CS0-003 Practice